Opened 16 years ago

Closed 16 years ago

Last modified 13 years ago

#3205 closed task (fixed)

cups-1.4.5, with security fix

Reported by: ken@… Owned by: Randy McMurchy
Priority: normal Milestone:
Component: BOOK Version: SVN
Severity: medium Keywords:
Cc:

Description

Version upgrade, includes fix for CVE-2010-2941. From the mitre report:

ipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate memory for attribute values with invalid string data types, which allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly execute arbitrary code via a crafted IPP request.

Loads of other fixes, see ​http://www.cups.org/articles.php?L597

Change History (3)

comment:1 by Randy McMurchy, 16 years ago

Owner: changed from blfs-book@… to Randy McMurchy
Status: new → assigned

I'm installing this right at this moment. I'll update the book.

comment:2 by Randy McMurchy, 16 years ago

Resolution: → fixed
Status: assigned → closed

Updated BLFS to CUPS-1.4.5

comment:3 by bdubbs@…, 13 years ago

Milestone: 6.7

Milestone 6.7 deleted

Note: See TracTickets for help on using tickets.